Skip to main content
Maintainers -ImageJodie-Lee Barnard

Audit & Software Procedures

Software Approval Process

OET-ISMS-POL-012

Purpose

To ensure that new software used within the organization is reviewed for security, data protection, and business necessity before approval.

Responsibilities

  • Requester: Provides business justification
  • Process owner (IT): Performs security and risk review
  • Management: Approves or rejects based on risk.

This process applies to all new software, SaaS tools, browser extensions, plugins, and open-source tools used for business purposes.

Policy document

Access the current version of the policy

Corrective Action Procedure

OET-ISMS-POL-013

Purpose

The purpose of this procedure is to ensure that all identified nonconformities within the ISMS are corrected in a timely, controlled, and traceable manner through documented corrective actions.

Scope

This procedure applies to all nonconformities identified during internal audits, external audits, incident reviews, monitoring activities, and day-to-day ISMS operations.

Policy document

Access the current version of the policy

Internal Audit Procedure

OET-ISMS-POL-014

Purpose

This procedure establishes the framework for conducting internal audits of the Information Security Management System (ISMS) to ensure compliance with ISO 27001:2022 requirements, organizational policies, and applicable legal and regulatory requirements. Internal audits verify the effectiveness of information security controls and identify opportunities for improvement.

Scope

This procedure applies to all components of Open Energy Transition's ISMS including:

  • Information security policies and procedures
  • Risk assessment and treatment processes
  • Security controls implementation (ISO 27001:2022 Annex A controls)
  • Asset management and data protection
  • Access control and identity management
  • Physical and environmental security
  • Operations security and network management
  • Incident management and business continuity
  • Supplier relationships and cloud services
  • Compliance with legal and regulatory requirements

Policy document

Access the current version of the policy

List of Applicable Standards and Regulations

OET-ISMS-POL-015

Purpose

The purpose of this list is to identify and document all relevant legal, statutory, regulatory, and contractual requirements related to information security that Open Energy Transition (OET) must comply with.

Scope

This policy applies to all OET activities, including software development , environmental consultancy, data management, and international research collaborations.

Policy document

Access the current version of the policy

List of all stakeholders/interested parties

OET-ISMS-POL-016

Purpose

The purpose of this list is to define the internal and external stakeholders (interested parties) relevant to the Information Security Management System (ISMS) of Open Energy Transition (OET). This policy ensures that OET identifies, monitors, and reviews the security requirements of these parties to maintain the confidentiality, integrity, and availability of its energy modeling services and software.

Scope

This policy applies to all operations within OET, including software development (PyPSA, Linopy, etc.), consultancy services, and data management.

Policy document

Access the current version of the policy

Artificial Intelligence (AI) Governance and Security Policy

OET-ISMS-POL-020

Purpose

The purpose of this policy is to define the principles for the secure and ethical use of AI systems within OET. This policy applies to all AI applications, including General Purpose AI (GPAI) like Gemini, coding assistants like Cursor, and any custom models developed for energy modeling. It aligns with ISO 27001 Clause 4.1 by considering the organizational context and stakeholders.

Policy document

Access the current version of the policy

Information Systems Testing during Auditing

OET-ISMS-POL-021

Purpose

To ensure that technical testing activities performed during audits or third-party engagements do not cause service disruptions, data breaches, or unauthorized changes to OET's operational systems.

Roles & Responsibilities

ISO: Owns this policy; must be present during technical testing on production systems; approves test plans jointly with the Head of Software Engineering. Head of Software Engineering: Approves test plans; ensures technical safeguards are in place during testing; validates post-test system integrity.

Policy document

Access the current version of the policy